At RSA Conference 2026 in San Francisco, Cisco announced a sweeping set of security capabilities designed to meet the rapid rise of AI agents in enterprise operations.
“AI agents aren’t just making existing work faster; they’re a new workforce of co-workers that dramatically expand what organizations can accomplish,”
said Jeetu Patel, President and Chief Product Officer at Cisco.
The headline announcements include the extension of Zero Trust Access to AI agents through Cisco Identity Intelligence, a new self-service security testing tool called AI Defense: Explorer Edition, an open-source agent security framework named DefenseClaw, and a major expansion of AI-powered threat response capabilities inside Splunk.
Together, these represent one of the most comprehensive attempts yet by a major vendor to build a security foundation purpose-built for agentic AI.
Breaking Down the Announcements
The first and most foundational announcement is the extension of Zero Trust Access to AI agents. Until now, this framework largely applied to human identities. Cisco is expanding it through updates to its Duo identity platform and Secure Access product. Organizations can register agents, assign them to an accountable human owner, and restrict access to only the tools and data required for specific tasks. An MCP gateway (a routing layer for agent-to-tool communications) ensures all agent activity is visible and auditable, eliminating the blind spots legacy tools often create.
The second major announcement is AI Defense: Explorer Edition, a self-service tool that allows developers and security teams to stress-test AI agents before they reach production. Built on the same validation engine used by Cisco’s Global 2000 customers, it runs multi-turn adversarial simulations that mimic the sustained, manipulative interactions of a bad actor. It tests resilience against prompt injection, jailbreaks, and unsafe outputs. The tool generates exportable security reports for compliance review and integrates directly into developer pipelines through GitHub Actions, GitLab, Jenkins, and other platforms.
Alongside this, Cisco is releasing an Agent Runtime SDK that embeds security controls directly into agent code during the build process and an LLM Security Leaderboard that scores AI models on resilience to attacks, helping organizations choose which models to trust.
The third key announcement is DefenseClaw, an open-source secure agent framework designed to remove friction between development and security teams. It bundles a suite of scanning and inventory tools including Skills Scanner, MCP Scanner, AI BoM, and CodeGuard, ensuring that every agent skill is scanned, every MCP server verified, and every AI asset cataloged automatically. Cisco plans to integrate DefenseClaw with NVIDIA’s OpenShell sandbox environment, automating security checks that previously required manual steps or separate tool installations.
The fourth pillar is the expansion of AI-powered capabilities inside Splunk, Cisco’s security operations platform. The headline addition is the Agentic SOC, a suite of specialized AI agents including a Detection Builder, Triage Agent, Malware Threat Reversing Agent, and Guided Response Agent. These shift security operations from a manual, reactive model to one in which routine investigation and response tasks run autonomously at machine speed. Supporting these functions are new features such as Exposure Analytics for real-time asset risk scoring, Detection Studio for managing the full detection engineering lifecycle, and Federated Search for correlating data across multiple environments in a single query.
Why This Announcement Matters Now
Cisco’s ambition is grounded in a stark reality the company uncovered in its own research. Eighty-five percent of major enterprise customers are already experimenting with AI agents, but only 5% have moved them into live production.




